First published: Fri Jan 20 2023(Updated: )
Predictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later, and versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 179**** and prior, and versions 1.074 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-xMy/z (x=32,64,96, y=T, z=D,DSS)) with serial number 17X**** or later, and versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-xMy/z (x=32,64,96, y=T, z=D,DSS)) with serial number 179**** and prior, and versions 1.074 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MT/DS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MT/DSS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ-xMy/z (x=24,40,60, y=T,R, z=ES,ESS) versions 1.042 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ-xMy/ES-A (x=24,40,60, y=T,R) versions 1.043 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5S-xMy/z (x=30,40,60,80, y=T,R, z=ES,ESS) versions 1.003 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MR/DS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU versions 33 and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU versions 66 and prior allows a remote unauthenticated attacker to access the Web server function by guessing the random numbers used for authentication from several used random numbers.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Fx5u-80mt\/ess Firmware | ||
Mitsubishielectric Fx5u-80mt\/ess | ||
Mitsubishielectric Fx5u-32mt\/dss Firmware | ||
Mitsubishielectric Fx5u-32mt\/dss | ||
Mitsubishielectric Fx5u-64mt\/dss Firmware | ||
Mitsubishielectric Fx5u-64mt\/dss | ||
Mitsubishielectric Fx5u-80mt\/dss Firmware | ||
Mitsubishielectric Fx5u-80mt\/dss | ||
Mitsubishielectric Fx5uc-32mt\/d Firmware | ||
Mitsubishielectric Fx5uc-32mt\/d | ||
Mitsubishielectric Fx5uc-64mt\/d Firmware | ||
Mitsubishielectric Fx5uc-64mt\/d | ||
Mitsubishielectric Fx5uc-96mt\/d Firmware | ||
Mitsubishielectric Fx5uc-96mt\/d | ||
Mitsubishielectric Fx5uc-32mt\/dss Firmware | ||
Mitsubishielectric Fx5uc-32mt\/dss | ||
Mitsubishielectric Fx5uc-64mt\/dss Firmware | ||
Mitsubishielectric Fx5uc-64mt\/dss | ||
Mitsubishielectric Fx5uc-96mt\/dss Firmware | ||
Mitsubishielectric Fx5uc-96mt\/dss | ||
Mitsubishielectric Fx5uc-32mt\/ds-ts Firmware | <1.280 | |
Mitsubishielectric Fx5uc-32mt\/ds-ts | ||
Mitsubishielectric Fx5uc-32mt\/dss-ts Firmware | <1.280 | |
Mitsubishielectric Fx5uc-32mt\/dss-ts | ||
Mitsubishielectric Fx5uc-32mr\/ds-ts Firmware | <1.280 | |
Mitsubishielectric Fx5uc-32mr\/ds-ts | ||
Mitsubishielectric R00cpu Firmware | ||
Mitsubishielectric R00cpu | ||
Mitsubishielectric R01cpu Firmware | ||
Mitsubishielectric R01cpu | ||
Mitsubishielectric R02cpu Firmware | ||
Mitsubishielectric R02cpu | ||
Mitsubishielectric R04cpu Firmware | ||
Mitsubishielectric R04cpu | ||
Mitsubishielectric R08cpu Firmware | ||
Mitsubishielectric R08cpu | ||
Mitsubishielectric R16cpu Firmware | ||
Mitsubishielectric R16cpu | ||
Mitsubishielectric R32cpu Firmware | ||
Mitsubishielectric R32cpu | ||
Mitsubishielectric R120cpu Firmware | ||
Mitsubishielectric R120cpu | ||
Mitsubishielectric R04encpu Firmware | ||
Mitsubishielectric R04encpu | ||
Mitsubishielectric R08encpu Firmware | ||
Mitsubishielectric R08encpu | ||
Mitsubishielectric R16encpu Firmware | ||
Mitsubishielectric R16encpu | ||
Mitsubishielectric R32encpu Firmware | ||
Mitsubishielectric R32encpu | ||
Mitsubishielectric R120encpu Firmware | ||
Mitsubishielectric R120encpu | ||
Mitsubishielectric Fx5uj-24mt\/es Firmware | <1.042 | |
Mitsubishielectric Fx5uj-24mt\/es | ||
Mitsubishielectric Fx5uj-40mt\/es Firmware | <1.042 | |
Mitsubishielectric Fx5uj-40mt\/es | ||
Mitsubishielectric Fx5uj-60mt\/es Firmware | <1.042 | |
Mitsubishielectric Fx5uj-60mt\/es | ||
Mitsubishielectric Fx5uj-24mr\/es Firmware | <1.042 | |
Mitsubishielectric Fx5uj-24mr\/es | ||
Mitsubishielectric Fx5uj-40mr\/es Firmware | <1.042 | |
Mitsubishielectric Fx5uj-40mr\/es | ||
Mitsubishielectric Fx5uj-60mr\/es Firmware | <1.042 | |
Mitsubishielectric Fx5uj-60mr\/es | ||
Mitsubishielectric Fx5uj-24mt\/ess Firmware | <1.042 | |
Mitsubishielectric Fx5uj-24mt\/ess | ||
Mitsubishielectric Fx5uj-40mt\/ess Firmware | <1.042 | |
Mitsubishielectric Fx5uj-40mt\/ess | ||
Mitsubishielectric Fx5uj-60mt\/ess Firmware | <1.042 | |
Mitsubishielectric Fx5uj-60mt\/ess | ||
Mitsubishielectric Fx5uj-24mt\/es-a Firmware | <1.043 | |
Mitsubishielectric Fx5uj-24mt\/es-a | ||
Mitsubishielectric Fx5uj-40mt\/es-a Firmware | <1.043 | |
Mitsubishielectric Fx5uj-40mt\/es-a | ||
Mitsubishielectric Fx5uj-60mt\/es-a Firmware | <1.043 | |
Mitsubishielectric Fx5uj-60mt\/es-a | ||
Mitsubishielectric Fx5uj-24mr\/es-a Firmware | <1.043 | |
Mitsubishielectric Fx5uj-24mr\/es-a | ||
Mitsubishielectric Fx5uj-40mr\/es-a Firmware | <1.043 | |
Mitsubishielectric Fx5uj-40mr\/es-a | ||
Mitsubishielectric Fx5uj-60mr\/es-a Firmware | <1.043 | |
Mitsubishielectric Fx5uj-60mr\/es-a | ||
Mitsubishielectric Fx5s-30mt\/es Firmware | <1.003 | |
Mitsubishielectric Fx5s-30mt\/es | ||
Mitsubishielectric Fx5s-40mt\/es Firmware | <1.003 | |
Mitsubishielectric Fx5s-40mt\/es | ||
Mitsubishielectric Fx5s-60mt\/es Firmware | <1.003 | |
Mitsubishielectric Fx5s-60mt\/es | ||
Mitsubishielectric Fx5s-80mt\/es Firmware | <1.003 | |
Mitsubishielectric Fx5s-80mt\/es | ||
Mitsubishielectric Fx5s-30mr\/es Firmware | <1.003 | |
Mitsubishielectric Fx5s-30mr\/es | ||
Mitsubishielectric Fx5s-40mr\/es Firmware | <1.003 | |
Mitsubishielectric Fx5s-40mr\/es | ||
Mitsubishielectric Fx5s-60mr\/es Firmware | <1.003 | |
Mitsubishielectric Fx5s-60mr\/es | ||
Mitsubishielectric Fx5s-80mr\/es Firmware | <1.003 | |
Mitsubishielectric Fx5s-80mr\/es | ||
Mitsubishielectric Fx5s-30mt\/ess Firmware | <1.003 | |
Mitsubishielectric Fx5s-30mt\/ess | ||
Mitsubishielectric Fx5s-40mt\/ess Firmware | <1.003 | |
Mitsubishielectric Fx5s-40mt\/ess | ||
Mitsubishielectric Fx5s-60mt\/ess Firmware | <1.003 | |
Mitsubishielectric Fx5s-60mt\/ess | ||
Mitsubishielectric Fx5s-80mt\/ess Firmware | <1.003 | |
Mitsubishielectric Fx5s-80mt\/ess | ||
Mitsubishi Electric MELSEC iQ-F Series with serial number 17X**** or later: FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS: Versions 1.280 and prior FX5UC-xMy/z x=32,64,96 y=T, z=D,DSS | <=1.280 | |
Mitsubishi Electric FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS | <=1.280 | |
Mitsubishi Electric FX5UC-xMy/z x=32,64,96 y=T, z=D,DSS | <=1.280 | |
Mitsubishi Electric MELSEC iQ-F Series with serial number 179**** and prior: FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS: Versions 1.074 and prior FX5UC-xMy/z x=32,64,96 y=T, z=D,DSS | <=1.074 | |
Mitsubishi Electric FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS | <=1.074 | |
Mitsubishi Electric FX5UC-xMy/z x=32,64,96 y=T, z=D,DSS | <=1.074 | |
Mitsubishi Electric MELSEC iQ-F Series FX5UC-32MT/DS-TS, FX5UC-32MT/DSS-TS, FX5UC-32MR/DS-TS | <=1.280 | |
Mitsubishi Electric FX5UJ-xMy/z x=24,40,60, y=T,R, z=ES,ESS | <=1.042 | |
Mitsubishi Electric FX5UJ-xMy/ES-A* x=24,40,60, y=T,R | <=1.043 | |
Mitsubishi Electric FX5S-xMy/z x=30,40,60,80, y=T,R, z=ES,ESS | <=1.003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-40267 is rated as critical with a CVSS score of 9.1.
To fix the vulnerability, users should apply the security patches provided by Mitsubishi Electric Corporation for the affected firmware versions.
Check the list of affected firmware versions provided by Mitsubishi Electric Corporation to determine if your device is vulnerable to CVE-2022-40267.